{"id":"SUSE-SU-2026:23253-1","summary":"Security update for rsync","details":"This update for rsync fixes the following issues:\n\n- CVE-2026-53783: rrsync restricted-directory escape (bsc#1269041).\n- CVE-2026-53784: Daemon module-root chdir escape under \"use chroot = no\" (bsc#1269042).\n- CVE-2026-53785: --relative implied-parent creation escapes the destination tree (bsc#1269043).\n- CVE-2026-53786: Daemon --filter merge file bypasses the module filter list (bsc#1269044).\n- CVE-2026-53788: Daemon name-converter accepts newline-bearing names into its line protocol (bsc#1269046).\n- CVE-2026-53789: Malicious sender expands --delete scope by reclassifying an implied parent (bsc#1269047).\n- CVE-2026-53790: Command / argument injection via unquoted peer- or host-controlled values (bsc#1269048).\n- CVE-2026-53791: PROXY-protocol mode lets a direct client spoof the daemon's source address (bsc#1269049).\n- CVE-2026-53792: Receiver-supplied zero checksum block length drives sender matching negative (bsc#1269050).\n- CVE-2026-53793: Chroot \"/./\" inner-module escape via a parent-component symlink (bsc#1269051).\n- CVE-2026-53794: Remote peer disables the per-allocation sanity cap via --max-alloc=0 (bsc#1269052).\n- CVE-2026-53795: Receiver write escape via an absolute --temp-dir / --link-dest disabling rename/link confinement\n  (bsc#1269053).\n- CVE-2026-53796: Non-daemon receiver destination-chdir symlink race (bsc#1269054).\n- CVE-2026-53797: Sender source-tree parent-component symlink race -\u003e out-of-tree disclosure (bsc#1269055).\n- CVE-2026-53798: Daemon name-converter empty response maps an unknown name to uid/gid 0 (bsc#1269045).\n- CVE-2026-53799: Receiver ACL/xattr application follows a symlink-race -\u003e arbitrary ACL set (bsc#1269056).\n- CVE-2026-53800: Sender --remove-source-files unlink follows a parent-component symlink race -\u003e arbitrary file deletion\n  outside the source tree (bsc#1269057).\n- CVE-2026-53801: Sender/daemon directory-scan enumeration escapes the transfer root / module -\u003e out-of-tree disclosure\n  (bsc#1269058).\n- CVE-2026-53802: Arbitrary file read / transfer-shaping via symlinked operator-supplied input files (bsc#1269039).\n- CVE-2026-53803: Arbitrary file write / privilege escalation via symlinked operator-supplied output paths\n  (bsc#1269040).\n- CVE-2026-70452: `hosts deny` fails OPEN when a configured hostname cannot be resolved, admitting the host it was meant\n  to block (bsc#1273441).\n- CVE-2026-70453: Quadratic CPU exhaustion in hash_search() from a crafted equal-weak-checksum chain (bsc#1273440).\n- CVE-2026-70454: rsync-ssl establishes an unauthenticated TLS connection (bsc#1273439).\n- CVE-2026-70455: Peer-controlled Zstandard worker exhaustion on an rsync daemon (bsc#1273438).\n- CVE-2026-70456: Remote out-of-bounds heap write in read_args() when the argument count lands exactly on maxargs\n  (bsc#1273437).\n- CVE-2026-70457: Attacker-chosen-offset write in parse_size_arg() error formatting (bsc#1273436).\n- CVE-2026-70458: Out-of-bounds write from a FLAG_HLINKED file entry accepted without -H (bsc#1273435).\n- CVE-2026-70459: Per-connection daemon child crash from a crafted first incremental file list with a non-directory\n  transfer root (bsc#1273434).\n- CVE-2026-70460: Daemon module-root escape through a peer-supplied --partial-dir / --backup-dir resolving via an in-\n  module symlink (bsc#1273433).\n- CVE-2026-70461: Peer-driven one-byte heap out-of-bounds write in add_implied_include() (bsc#1273432).\n- CVE-2026-70462: Peer-supplied MSG_IO_TIMEOUT defeats the client's own I/O timeout (bsc#1273431).\n- CVE-2026-70463: \"auth users\" ignores documented comma-only parsing, silently skipping a deny/read-only rule\n  (bsc#1273430).\n- CVE-2026-70464: Unauthenticated pre-transfer handshake DoS locks out an rsync daemon module (bsc#1273429).\n","modified":"2026-08-27T18:23:23.930861235Z","published":"2026-08-24T14:42:20Z","related":["CVE-2026-43617","CVE-2026-43618","CVE-2026-43619","CVE-2026-43620","CVE-2026-53783","CVE-2026-53784","CVE-2026-53785","CVE-2026-53786","CVE-2026-53788","CVE-2026-53789","CVE-2026-53790","CVE-2026-53791","CVE-2026-53792","CVE-2026-53793","CVE-2026-53794","CVE-2026-53795","CVE-2026-53796","CVE-2026-53797","CVE-2026-53798","CVE-2026-53799","CVE-2026-53800","CVE-2026-53801","CVE-2026-53802","CVE-2026-53803","CVE-2026-70452","CVE-2026-70453","CVE-2026-70454","CVE-2026-70455","CVE-2026-70456","CVE-2026-70457","CVE-2026-70458","CVE-2026-70459","CVE-2026-70460","CVE-2026-70461","CVE-2026-70462","CVE-2026-70463","CVE-2026-70464"],"upstream":["CVE-2026-43617","CVE-2026-43618","CVE-2026-43619","CVE-2026-43620","CVE-2026-53783","CVE-2026-53784","CVE-2026-53785","CVE-2026-53786","CVE-2026-53788","CVE-2026-53789","CVE-2026-53790","CVE-2026-53791","CVE-2026-53792","CVE-2026-53793","CVE-2026-53794","CVE-2026-53795","CVE-2026-53796","CVE-2026-53797","CVE-2026-53798","CVE-2026-53799","CVE-2026-53800","CVE-2026-53801","CVE-2026-53802","CVE-2026-53803","CVE-2026-70452","CVE-2026-70453","CVE-2026-70454","CVE-2026-70455","CVE-2026-70456","CVE-2026-70457","CVE-2026-70458","CVE-2026-70459","CVE-2026-70460","CVE-2026-70461","CVE-2026-70462","CVE-2026-70463","CVE-2026-70464"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-202623253-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269039"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269040"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269041"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269042"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269043"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269044"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269045"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269046"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269047"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269048"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269049"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269050"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269051"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269052"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269053"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269054"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269055"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269056"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269057"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269058"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269060"},{"type":"REPORT","url":"https://bugzilla.suse.com/1273429"},{"type":"REPORT","url":"https://bugzilla.suse.com/1273430"},{"type":"REPORT","url":"https://bugzilla.suse.com/1273431"},{"type":"REPORT","url":"https://bugzilla.suse.com/1273432"},{"type":"REPORT","url":"https://bugzilla.suse.com/1273433"},{"type":"REPORT","url":"https://bugzilla.suse.com/1273434"},{"type":"REPORT","url":"https://bugzilla.suse.com/1273435"},{"type":"REPORT","url":"https://bugzilla.suse.com/1273436"},{"type":"REPORT","url":"https://bugzilla.suse.com/1273437"},{"type":"REPORT","url":"https://bugzilla.suse.com/1273438"},{"type":"REPORT","url":"https://bugzilla.suse.com/1273439"},{"type":"REPORT","url":"https://bugzilla.suse.com/1273440"},{"type":"REPORT","url":"https://bugzilla.suse.com/1273441"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43617"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43618"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43619"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43620"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-53783"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-53784"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-53785"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-53786"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-53788"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-53789"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-53790"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-53791"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-53792"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-53793"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-53794"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-53795"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-53796"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-53797"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-53798"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-53799"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-53800"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-53801"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-53802"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-53803"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-70452"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-70453"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-70454"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-70455"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-70456"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-70457"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-70458"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-70459"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-70460"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-70461"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-70462"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-70463"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-70464"}],"affected":[{"package":{"name":"rsync","ecosystem":"SUSE:Linux Micro 6.0","purl":"pkg:rpm/suse/rsync&distro=SUSE%20Linux%20Micro%206.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.2.7-8.1"}]}],"ecosystem_specific":{"binaries":[{"rsync":"3.2.7-8.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:23253-1.json"}}],"schema_version":"1.9.0"}